Privacy Policy
Effective August 2, 2026
Fifteen is a local-first desktop app. It signs in to messaging accounts you already have — Telegram, Signal, WhatsApp, Slack, iMessage and Gmail — and brings them together in one client that runs on your Mac. Your messages, contacts and files are downloaded by your own computer from your own accounts and stored on your own computer. In the ordinary course of using Fifteen, they never reach our servers.
This policy explains the narrow set of cases where personal data does reach Fifteen Labs, Inc. (“Fifteen”, “we”, “us”), what we do with it, who we share it with, and the rights you have over it. We have tried to write it so that you can actually tell what happens to your data.
The short version
- Your messages stay on your Mac. Fifteen downloads them from your own accounts onto your own computer and keeps them there. In ordinary use they never reach us.
- We cannot read your messages. The content that does go to our servers — chats you share, and your private notes — is encrypted on your device with keys we never hold. We store ciphertext.
- Sharing is opt-in, one chat at a time. Nothing is uploaded until you share it, and you can revoke access or delete it afterwards.
- We don't track you. There is no analytics or telemetry in the app, and no cookies, pixels or third-party scripts on our websites.
- Fifteen blocks other people's tracking. Remote images in the emails you read are blocked by default, so tracking pixels can't report that you opened them.
- We never sell your data, and we never share it for advertising.
- We never train AI on your data. AI features run only when you ask for them, and what you send goes to a provider contractually barred from training on it.
- Transcription happens on your Mac. Voice messages and calls are transcribed by a model running locally; the audio is never uploaded anywhere.
- What we hold is deliberately small. Your sign-in identity, your subscription record, the handles you publish so people can share chats with you, encrypted content, and crash reports.
- You can delete it. Disconnecting an account erases its local data, and deleting your Fifteen account erases what we hold.
This is an orientation, not a substitute — the sections below are the policy.
Contents
- What this Privacy Policy covers
- Two tiers: your device and our servers
- Personal data we handle
- Where the data comes from
- How we use personal data
- How we share personal data
- AI features
- Cookies, analytics and tracking
- Security
- Retention and deletion
- Children
- Your choices and controls
- US state privacy rights
- EU, UK and Swiss data protection rights
- International transfers
- Changes to this policy
- Contact us
1. What this Privacy Policy covers
This policy covers the Fifteen desktop app, our websites at fifteen.app and its subdomains, and the backend services that support them.
It does not cover the messaging platforms you connect to Fifteen. Telegram, Signal, WhatsApp, Slack, Apple and Google each run their own services under their own privacy policies. When you use Fifteen to read or send messages, you are using those services through your own accounts, and their handling of your data remains between you and them. Nor does it cover third-party sites you reach by clicking a link inside a message.
2. Two tiers: your device and our servers
Almost every privacy question about Fifteen comes down to which of two tiers a piece of data lives in. Throughout this policy we label them:
- On your device. Stored in a folder on your Mac (
~/.fifteen). Message history, contacts, attachments, avatars, transcripts, search indexes, settings and the credentials for your connected accounts all live here. This data is not transmitted to us, is not backed up by us, and is not readable by us. - On our servers. A deliberately small set: your sign-in identity, your subscription record, the handles you publish so other people can share chats with you, your encryption key material in wrapped (unreadable) form, chats you explicitly choose to share, your AI agent threads, and crash reports.
Chat content you share is end-to-end encrypted. When you share a chat with another Fifteen user, message text, sender names and attachments are encrypted on your device before upload, using keys derived from a root key that never leaves your devices in readable form. Our servers store ciphertext and hand it to the people you granted access. We cannot read it, and we cannot recover it for you if you lose your key material and your recovery code.
3. Personal data we handle
3.1 Account and profile data — on our servers
When you create a Fifteen account you sign in through our identity provider (Auth0). We receive and store the identity claims it issues: your email address and whether it is verified, your name and nickname, your profile picture URL, your locale and time zone, and the identifier that links your account across sign-ins. We do not receive or store your password; authentication is handled entirely by the identity provider.
If you are part of an organization, we also store the organization's name, your membership and role in it, and any email addresses you invite.
3.2 Handle directory — on our servers
So other Fifteen users can share a chat with you, Fifteen registers the handles of your connected accounts — for example your Telegram username, your Slack handle or your email address — in a lookup directory alongside your public encryption keys. Any Fifteen client can look up a handle in this directory to find the corresponding user and key, which is what makes it possible to encrypt a share to you. Publishing a handle is what makes you findable; if you would rather not be findable by a given handle, do not connect that account, or contact us to have the entry removed.
3.3 Payment data — on our servers and Stripe's
Paid subscriptions are handled by Stripe. Card numbers and other payment credentials go directly from you to Stripe through their hosted checkout and billing portal; they never pass through, and are never stored on, Fifteen systems. We store a lean projection of your billing state: your Stripe customer and subscription identifiers, your plan tier and status, the current billing period, your AI spend cap, and metered usage counters.
3.4 Connected account data — on your device
This is by far the largest category of personal data Fifteen touches, and none of it reaches us. When you connect an account, the app syncs from that platform onto your Mac and keeps a local copy of:
- messages and their metadata — text, timestamps, read receipts, reactions, replies, edits and deletions;
- attachments and media — photos, videos, voice messages, documents;
- contacts, chats, channels and groups — names, usernames, phone numbers, email addresses, profile photos, and for Slack, profile fields such as job title and presence;
- email — messages, threads, labels and attachments from the Gmail accounts you connect;
- derived data — search indexes, and transcripts of voice messages and calls, which are produced by a speech-to-text model that runs entirely on your Mac. Audio is never sent to us or to any cloud transcription service;
- credentials — the OAuth tokens and session keys that keep those accounts connected, stored in the macOS Keychain.
This necessarily includes personal data about the people you communicate with. It is on your device because you put it there, in the same way that a desktop email client keeps a local mailbox. We are not able to access it.
3.5 Shared chats — on our servers, encrypted
Sharing is off by default and opt-in per chat. When you share a chat, the app uploads that chat's messages, sender names and handles, avatars and attachments to our backend — each item encrypted on your device first, and each recipient's copy of the chat key wrapped to that recipient's public key. We store the resulting ciphertext, the grant records that say who has access, and the minimal metadata needed to route and de-duplicate it (for example, the size of a blob and a content fingerprint). You can revoke a grant or delete a shared chat at any time.
3.6 AI data — on our servers, and with AI providers
See section 7 for how the AI features work. In short: conversation threads from the in-app AI agent are stored on our backend so they follow you between devices, and prompts you submit to Fifteen's AI assistant — which can include message content you choose to give it as context — pass through our gateway to a third-party model provider.
3.7 Diagnostic data — on our servers and Sentry's
Released builds of the app send crash and error reports to Sentry, hosted in the European Union (Germany). A report contains the crash message and stack trace, the app version, your operating system and device model, and application log lines at warning or error level. These are diagnostic records, not message content, but a log line can incidentally contain an identifier such as an account ID or a file name. You can turn crash reporting off in the app's settings.
3.8 Website data — on our servers
Our websites are static pages with no cookies, no analytics and no third-party scripts. Our hosting provider processes the network information inherent in serving a page — IP address, user agent, the URL requested — for delivery, caching and abuse prevention.
3.9 What we do not collect
- No product analytics. There is no analytics or telemetry SDK in the app. We do not record which features you use, which chats you open, or how long you spend in the app.
- No advertising or tracking SDKs, and no advertising identifiers.
- No location data. We do not read your device's location.
- No biometric data. Voice and call transcription runs locally and produces no voiceprint or biometric template.
- No profiling or automated decision-making that produces legal or similarly significant effects.
4. Where the data comes from
| Source | What we receive |
|---|---|
| Directly from you | Sign-in identity, organization and invitation details, billing email, support correspondence, the chats you choose to share, prompts you send to AI features. |
| Automatically from your device | Crash and error reports (released builds, unless you turn them off); the network information inherent in any connection to our backend or websites. |
| From the platforms you connect, at your direction | Everything under 3.4 — retrieved by your device from your own accounts, and stored only on your device. |
| From our service providers | Identity claims from Auth0; subscription and payment status from Stripe. |
5. How we use personal data
| Purpose | What it involves |
|---|---|
| Providing the app | Signing you in, keeping your connected accounts working, syncing your settings, and delivering shared chats to the people you granted access. |
| Encryption and device management | Storing your wrapped key material and public keys so a new device of yours can be verified and enrolled, and so shares can be encrypted to you. |
| Billing | Creating and managing your subscription, metering AI usage, and enforcing spend caps. |
| Support | Answering your questions and investigating problems you report. |
| Stability and security | Diagnosing crashes and errors, detecting abuse, and protecting the integrity of the service. |
| Legal and compliance | Meeting tax, accounting and other legal obligations, and responding to lawful requests. |
We do not use personal data for advertising, for profiling, or to train AI models — ours or anyone else's.
6. How we share personal data
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose it to the service providers listed below, who process it on our instructions and are bound by contract to use it only to provide their service to us.
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Auth0 (Okta) | Sign-in and identity | Email, name, avatar, authentication events | United States |
| Clockwork Labs (SpacetimeDB) | Backend database hosting | Everything in the “on our servers” tier, including shared-chat ciphertext | TODO — SpacetimeDB maincloud region |
| Cloudflare | Website and API hosting, object storage for attachment blobs, AI gateway | Website traffic, encrypted attachment blobs, AI request content | Global edge network |
| Stripe | Payments and subscriptions | Billing email, account identifiers, payment details you give Stripe directly | United States |
| Sentry | Crash and error reporting | Crash reports, stack traces, device context, warning and error logs | European Union (Germany) |
| AI model providers | Answering AI requests | Prompts and context you submit to AI features | See section 7 |
We also disclose personal data:
- To other Fifteen users, at your direction — the people you grant access to a shared chat receive that chat's content, and anyone can look up a published handle in the directory described in 3.2.
- To the messaging platforms you connect — when you send a message, it goes to that platform, as you would expect.
- For legal reasons — where we believe in good faith that disclosure is required by law, or is necessary to protect the rights, property or safety of Fifteen, our users or the public. Note that end-to-end encrypted content is not readable by us, so we cannot produce its plaintext in response to such a request.
- In a business transfer — if we are involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction, subject to this policy.
- With your consent, for anything else.
7. AI features
Fifteen has two distinct AI capabilities, and it matters which one you are using.
7.1 Fifteen's AI assistant
Requests from the assistant go to a gateway we operate, which authenticates you, applies your spend cap, meters usage for billing, and forwards the request to a third-party large language model provider through Cloudflare AI Gateway. What we send is what you submit: your prompt, plus whatever conversation context you choose to attach. We do not send your message history to the AI provider unless you ask the assistant to work with it.
We record the token counts needed to bill you. We do not use your prompts or their responses to train models, and our providers are engaged under terms that prohibit them from doing so.
7.2 Local coding agents
The agent panel can run third-party agents (such as Claude Code or Gemini CLI) as processes on your own machine. These are separate products with their own terms and privacy policies. When you use one, Fifteen passes it the context you have selected — typically a snapshot of the chat you are viewing — and the agent then sends that to its own provider under its own account and policies. Your agent conversation threads are stored on our backend so they are available across your devices.
Gmail data is subject to Google API Services User Data Policy limits. Fifteen does not transfer Gmail message content to AI models except where you explicitly direct it, and never uses it to develop, improve or train generalised AI models.
8. Cookies, analytics and tracking
Our websites set no cookies, run no analytics, and load no third-party scripts or pixels. The desktop app contains no analytics or advertising SDK.
Fifteen also works in the opposite direction: it blocks other people's tracking. Remote images and other network assets in the emails you read are blocked by default (“Sandboxed”), which prevents tracking pixels from reporting that you opened a message. You can relax this to a filtered mode that applies public ad- and tracker-blocking lists, or allow everything — globally, per sender, or per thread.
9. Security
- End-to-end encryption for shared chats and your private notes. Content is encrypted on your device with keys derived from a root key that our servers never see. Access is granted by wrapping a chat key to a recipient's public key; server-side key rotation is verified against a signature chain.
- Device linking with verification. Adding a device requires approval from a device you already have, confirmed by comparing a short emoji sequence, or a recovery code you keep yourself.
- Credentials in the macOS Keychain. Tokens and session keys for connected accounts are held in the system keychain rather than in plain files.
- Encrypted transport. All connections use TLS.
- Access control on the backend. Tables are private by default and readable only through per-caller views; every operation on shared content is grant-checked; anonymous connections are rejected.
- Payment isolation. Card data goes directly to Stripe and never touches our systems.
- Signed and notarised builds, released through an automated pipeline.
No system is perfectly secure, and we cannot guarantee that unauthorised access will never occur. Two things are worth being explicit about: the data on your Mac is protected by your Mac, so full disk encryption and a strong login password matter; and because your key material is yours alone, if you lose every enrolled device and your recovery code, your encrypted content cannot be recovered by anyone, including us.
10. Retention and deletion
- On your device. Kept until you remove it. Disconnecting an account deletes that platform's local data; deleting the app's data folder removes everything. Local diagnostic logs rotate after 7 days.
- Shared chats. Kept until you delete the chat or revoke access. Revoking a grant removes the recipient's ability to decrypt; deleting the chat removes the ciphertext, and orphaned attachment blobs are garbage-collected.
- Account data. Kept for as long as your account exists. When you delete your account, we delete your identity record, key material, handle directory entries, shared chats and agent threads. Backups and logs age out on their own cycle, normally within 90 days.
- Billing records. Retained for as long as tax and accounting law requires, typically seven years, even after account deletion.
- Crash reports. Retained by Sentry for 90 days.
11. Children
Fifteen is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at privacy@fifteen.app and we will delete it.
12. Your choices and controls
- Sharing is opt-in. No chat leaves your device until you share it, and you can revoke a grant or delete a shared chat at any time.
- Disconnect an account at any time, which deletes that platform's local data.
- Turn off crash reporting in settings.
- Control email network requests globally, per sender or per thread.
- Use AI features or don't — nothing is sent to an AI provider unless you ask for it.
- Delete your account from the app's settings, or by writing to privacy@fifteen.app.
13. US state privacy rights
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas or another state with a comprehensive privacy law, you have the right to know what personal data we have collected, to access a copy of it, to have it corrected, to have it deleted, and to not be discriminated against for exercising these rights. Some states also give you the right to opt out of the sale or sharing of personal data and of profiling — we do neither, so there is nothing to opt out of.
For the twelve months preceding the date of this policy, the categories of personal data we collected, the purposes, and the recipients are exactly those set out in sections 3, 5 and 6. The sensitive personal information we handle is limited to your account log-in credentials and the credentials for your connected accounts; we use them only to operate the service, never to infer characteristics about you.
Notice of no sale. We do not sell personal information and have not done so in the preceding twelve months. We have not sold or shared the personal information of consumers we know to be under 16.
To exercise a right, email privacy@fifteen.app. We will verify your request against the email address on your account, and respond within the time the applicable law allows (45 days in California, extendable once). You may use an authorised agent, in which case we will ask for proof of their authorisation. If we decline a request you may appeal by replying to our response; where your state provides one, you also have the right to complain to your Attorney General.
Nevada. Nevada residents may direct us not to sell their covered information. We do not sell it, but you may submit a request to privacy@fifteen.app.
14. EU, UK and Swiss data protection rights
Where the GDPR or UK GDPR applies, Fifteen Labs, Inc. is the controller of the personal data described in this policy. Note that for the data stored only on your device, we are not in a position to act as controller in any practical sense — we have no access to it.
14.1 Legal bases
| Processing | Legal basis |
|---|---|
| Providing the app and its features to you | Performance of a contract (Art. 6(1)(b)) |
| Billing and subscription management | Performance of a contract; legal obligation for tax records (Art. 6(1)(b), (c)) |
| Crash reporting, security and abuse prevention | Legitimate interests in a stable and secure service (Art. 6(1)(f)) |
| Handle directory | Performance of a contract — it is what makes sharing possible (Art. 6(1)(b)) |
| Responding to legal requests | Legal obligation (Art. 6(1)(c)) |
| Anything you separately agree to | Consent (Art. 6(1)(a)), withdrawable at any time |
14.2 Your rights
You have the right to access your personal data, to have it rectified, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent where processing is based on consent. To exercise any of them, email privacy@fifteen.app. We will respond within one month, extendable by two further months for complex requests.
You also have the right to lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office if you are in the United Kingdom. We would appreciate the chance to address your concern first.
15. International transfers
We are based in the United States, and some of our service providers process data there. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or Swiss equivalent as applicable), together with the technical measures described in section 9 — most importantly, that shared chat content is encrypted before it ever leaves your device. A copy of the relevant transfer safeguards is available on request.
16. Changes to this policy
We will update this policy as Fifteen changes. When we do, we will revise the effective date at the top. If the change is material, we will give you notice in the app or by email before it takes effect. Continuing to use Fifteen after a change takes effect means you accept the updated policy.
17. Contact us
Privacy questions and requests: privacy@fifteen.app
Everything else: support@fifteen.app
Fifteen Labs, Inc., a Delaware corporation
TODO — registered address, Delaware, United States